Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Apple can break Beeper without relying on the secure enclave: If Apple devices just send their serial number (IMEI for their GSM products), their servers can refuse to talk to hardware they didn't manufacture.


Non-Apple devices could just lie


Not if they require a certificate containing the serial number/imei/... + a nonce provided by Apple, signed with a private key/certificate stored in the secured enclave, loaded into the device when it's manufactured.


The GP comment was:

> Apple can break Beeper without relying on the secure enclave: If Apple devices just send their serial number

You have come full circle with the comment 4 posts up.


Beeper will know only a small number of valid serial numbers

If it ever becomes popular, there will be a lot of duplicate serial numbers. That's easy to detect and ban.


How does this address iMessages sent from non-iPhone devices?


If in the data sent across (via Apple servers) the IMEI and serial no of the device are also transmitted, then Apple can in that millisecond query on their various lists/inventories that this device is legit (activated device + IMEI + serial) and if all lights are green, proceed to deliver, otherwise drop it.

(perhaps different sets of data can be used, but it must be something that Apple already has, and the user has already provided (i.e. the iMessage email or the iMessage phone number, from the iPhone's enabled Settings)


As someone who once bought fake airpods on ebay, I can tell you that Apple can't do this.

I spent a number of days with them where they were trying to work out if they were fake. The serial number was real but they were fairly sure the number had been taken from a real product and reused, but were unable to say for sure.

I ended up just returning them (because of the ebay return window) but found it interesting that Apple couldn't easily check this, and was very aware of the issue.


you already have to do this to get certain apple services (including imessage) working on hackintoshes. turns out there's a really easy work-around: guess-and-check serial numbers on apple's web site until one works. they rate limit it a bit but you can usually find a working one without a terrible amount of hassle.


Do you mean that I now have a nice party trick - DoSing friends iPhone from sending iMessage? :)


If you have a FlipperZero, DoSing iPhone users with Bluetooth is a bit of fun!


I believe you can bruteforce/generate IMEIs somewhat easily. https://github.com/bstein/py-imei-generator




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: